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From: 

Sent: 

To: 

Subject: 


noreply@formstack.com 
Friday, January 18, 2019 3:39 PM 
Breaches, Data (SCA) 

Security Breach Notifications 


OS 7 s. 
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Formstack 


Formstack Submission For: Security Breach Notifications - With 
Addresses 

Submitted at 01/18/19 3:39 PM 

Business Name: Eltringham Law Group 

Is the business located in the United States?: Yes 

233 

Boca Raton, FL 33432 

• - I 

Commercial 

i 

Anjali Das 

_ _ __ _ _..___, ^c.- * 

Attorney 


Contact Address: 

Contact Address: 

Telephone Number: (312) 821-6164 

Extension: 


55 W Monroe Street 
Suite 3800 
Chicago, IL 60603 


Business Address: 

Foreign Business Address: 
Company Type: : 

Your Name: 

Title: 
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Email Address: 

Relationship to Org: 

Breach Type: 

Date Breach was Discovered: 

Number of Massachusetts Residents Affected: 

Person responsible for data breach.; 

Please give a detailed explanation of how the data 
breach occurred.; 

Please select the type of personal information 
that was included in the breached data.; 


Please check ALL of the boxes that apply to your 
breach.: 


For breaches involving paper: A lock or security 
mechanism was used to physically protect the 
data.: 

Physical access to systems containing persona! 
information was restricted to authorized 
personnel only.: 

Network configuration of breached system: 

For breaches involving electronic systems, 
complete the following: 

Does your business maintain a Written 
Information Security Program (WISP)?: 

All Massachusetts residents affected by the 
breach have been notified of the breach.: 


Anjali.Das@wilsonelser.com 
Third party provider 
Electronic 
12/05/2018 
3 

Unknown 

Please see letter emailed. 

Social Security Numbers - Selection(s) 
Driver's License = Seleetion(s) 

The person(s) with possession of personal 
information had authorized access = 
Selection(s) 

The breach was a result of a 
malicious/criminal act. = Selection(s) 

N/A 

Yes 

Internet Access Available 

Personal information stored on the breached 
system was password-protected and/or 
restricted by user permissions. = Selection(s) 

Yes : 

Yes 
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affected by the breach (check all that apply):: 


Option2 | US Mail 


Please explain your answer of Other Above: 


Date notices were first sent to Massachusetts 
residents (MM/.DD/YYYY): 


breach have been offered complimentary credit 
monitoring services 

Law enforcement has been notified of this data 
breach.: 


01/18/2019 


Please describe how your company responded to 
the breach. Include what changes were made or 
may be made to prevent another similar breach 
from occurring, including updating your WISP.: 


Yes / No: 


Please see letter. 


Yes 


File 1 Upload: 


View File 


File 2 Upload: 


File 3 Upload: 


File - 4 Upload: 


Copyright ©2019 Foirnstack, LLC. All rights reserved. This is a customer service email. 
Foimstack, 8604 Allisonville Road. Suite 300, Indianapolis, IN 46250 
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LTRINEHAM 

- LAW GROUP- 

«Date» (Format: Month Day, Year) 
«MemberFirstName» «MemberMiddieName» «MetnberLastName» «Suffix» 

«Address1» 

«Address2» 

«City», «State» «ZipCode» 


Dear «MemberFirstName» «Memberl.astName», 

We are writing to inform you of a data security incident at Eltringham Law Group (“ELG”) that may have resulted in the 
disclosure of your personal information, including your name, health information, and/or Social Security number. We 
sincerely apologize for any inconvenience or concern this incident may cause. This letter contains information about 
what happened, steps you can take to protect yourself, and resources we are making available to you. 

ELG learned that an unauthorized individual attempted to fraudulently wire funds from an ELG controlled account. 
ELG immediately launched an investigation to determine what happened. ELG retained a computer forensic firm to 
help identify what systems may have been accessed by unauthorized individuals and what information may have 
been accessible. As a result of that investigation, on December 5, 2018, we determined that some of your personal 
information, including your name, address, date of birth, Social Security number, driver’s license number and limited 
health information may have been accessible by an unauthorized individual. 

We have no evidence of the misuse of your information as a result of this incident, however, out of an abundance of 
caution and as a safeguard, we have secured the services of Kroll to provide identity monitoring at no cost to you 
for one year, Kroll is a global leader in risk mitigation and response, and their team has extensive experience helping 
people who have sustained an unintentional exposure of confidential data. Your identity monitoring services include 
Credit Monitoring, Fraud Consultation, and identity Theft Restoration. 

Visit «lDMonitonngURL>> to activate and take advantage of your identity monitoring services. 

You have until «Date» to activate your identity monitoring services. 

Membership Number: «Member ID» 

To receive credit services by mail instead of online, please call 1-???-???-????. Additional information describing your 
services is included with this letter. 

We take the security of all information in our control very seriously and are taking steps to help prevent a similar event 
from occurring in the future. This includes increasing employee cybersecurity awareness training, implementing 
enhanced authentication controls and more robust email password policies for our employees, and adding additional 
security measures surrounding our internal and external communications of personal information. 

Again, we sincerely apologize for any concern or inconvenience this may cause you, and we remain dedicated to 
protecting your information, now and in the future. Nothing is more important to us than your trust and we will continue 
to do whatever it takes to honor that trust because YOU are the lifeblood of our business, 

If you have questions, please do not hesitate to call 1 -???-???-????, Monday through Friday, 9:00 a.m. to 6:30 p.m. 
Eastern Time. Please have your membership number ready. 

Sincerely, 

David Eltringham 
CEO & Founder 
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Additional Important Information 

For residents of Hawaii, Michigan, Missouri, Virginia, Vermont, and North Carolina: 

It is recommended by state law that you remain vigilant for incidents of fraud and identity theft by reviewing credit card account 
statements and monitoring your credit report for unauthorized activity. 

For residents of Illinois, Iowa, Maryland, Missouri, North Carolina, Oregon, and West Virginia: 

It is required by state laws to inform you that you may obtain a copy of your credit report, free of charge, whether or not you 
suspect any unauthorized activity on your account. You may obtain a free copy of your credit report from each of the three 
nationwide credit reporting agencies. To order your free credit report, please visit www.annualcreditreport.com, or call toll-free 
at 1-877-322-8228. You can also order your annual free credit report by mailing a completed Annual Credit Report Request Form 
{available at https://www.consumer.ftc.gov/articles/0155-free-credit-reports) to: Annual Credit Report Request Service, P.O. Box 
105281, Atlanta, GA, 30348-5281. 

For residents of Iowa: 

State law advises you to report any suspected identity theft to law enforcement or to the Attorney General. 

For residents of Oregon: 

State laws advise you to report any suspected identity theft to law enforcement, including the Attorney General, and the Federal 
Trade Commission. 

For residents of Maryland, Rhode Island, Illinois, and North Carolina: 

You can obtain information from the Maryland and North Carolina Offices of the Attorney General and the Federal Trade 
Commission about fraud alerts, security freezes, and steps you can take toward preventing identity theft. 

Maryland Office of the Rhode Island Office of the North Carolina Office of the Federal Trade Commission 

Attorney General Attorney General Attorney General Consumer Response Center 

Consumer Protection Division Consumer Protection Consumer Protection Division 600 Pennsylvania Ave, NW 

200 St. Paul Place 150 South Main Street 9001 Mall Service Center Washington, DC 20580 

Baltimore, MD 21202 Providence Rl 02903 Raleigh, NC 27699-9001 1-877-IDTHEFT (438-4338) 

1-888-743-0023 1-401-274-4400 1-877-566-7226 www.ftc.gov/idtheft 

www.oag.state.md.uswww.riag.ri.govwww.ncdoj.com 

For residents of Massachusetts: 

it is required by state law that you are informed of your right to obtain a police report if you are a victim of identity theft 

For residents of all states: 

Fraud Alerts: You can place fraud alerts with the three credit bureaus by phone and online with Equifax (https://assets.equifax. 
com/assets/personal/Fraud_Alert_Request_Form.pdf) or Experian (https://www.experian.com/fraud/center.html). A fraud alert 
tells creditors to follow certain procedures, including contacting you, before they open any new accounts or change your existing 
accounts. For that reason, placing a fraud alert can protect you, but also may delay you when you seek to obtain credit. As of 
September 21, 2018, initial fraud alerts last for one year. Victims of identity theft can also get an extended fraud alert for seven 
years. The phone numbers for all three credit bureaus are at the bottom of this page. 

Monitoring: You should always remain vigilant and monitor your accounts for suspicious or unusual activity. 

Security Freeze: You also have the right to place a security freeze on your credit report. A security freeze is intended to prevent 
credit, loans, and services from being approved in your name without your consent. To place a security freeze on your credit 
report, you need to make a request to each consumer reporting agency. You may make that request by certified mail, overnight 
mail, regular stamped mail, or by following the instructions found at the websites listed below. The following information must 
be included when requesting a security freeze (note that if you are requesting a credit report for your spouse or a minor under 
the age of 16, this information must be provided for him/her as well): (1) full name, with middle initial and any suffixes; (2) Social 
Security number; (3) date of birth; (4) current address and any previous addresses for the past five years; and (5) any applicable 
incident report or complaint with a law enforcement agency or the Registry of Motor Vehicles. The request must also include a 
copy of a government-issued identification card and a copy of a recent utility bill or bank or insurance statement. It is essential 
that each copy be legible, display your name and current mailing address, and the date of issue. As of September 21,2018, it 
is free to place, lift, or remove a security freeze. You may also place a security freeze for children under the age of 16. You may 
obtain a free security freeze by contacting any one or more of the following national consumer reporting agencies: 

Equifax Security Freeze Experian Security Freeze TransUnion (FVAD) 

P.O. Box 105788 P.O. Box 9554 P.O. Box 2000 

Atlanta, GA 30348 Allen, TX 75013 Chester, PA 19022 

www.freeze.equifax.comwww.experian.com/freezefreeze.transunion.com 
800-525-6285 888-397-3742 800-680-7289 

More information can also be obtained by contacting the Federal Trade Commission listed above. 
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Kroll. 

TAKE ADVANTAGE OF YOUR IDENTITY MONITORING SERVICES 

You’ve been provided with access to the following services 1 from Kroll: 

Single Bureau Credit Monitoring 

You will receive alerts when there are changes to your credit data—for instance, when a new line of credit is applied 
for in your name. If you do not recognize the activity, you’ll have the option to call a Kroll fraud specialist, who can help 
you determine if it’s an indicator of identity theft. 

Fraud Consultation 

You have unlimited access to consultation with a Kroll fraud specialist. Support includes showing you the most 
effective ways to protect your identity, explaining your rights and protections under the law, assistance with fraud 
alerts, and interpreting how personal information is accessed and used, including investigating suspicious activity 
that could be tied to an identity theft event. 

Identity Theft Restoration 

If you become a victim of identity theft, an experienced Kroll licensed investigator will work on your behalf to resolve 
related issues. You will have access to a dedicated investigator who understands your issues and can do most of the 
work for you. Your investigator can dig deep to uncover the scope of the identity theft, and then work to resolve it. 



1 Kroll's activation website is only compatible with the current version or one version earlier of internet Explorer, Chrome, Firefox, and Safari. 
To receive credit services, you must be over the age of 18 and have established credit in the U.S., have a Social Security number in your 
name, and have a U.S. residential address associated with your credit file. 


470-0517 





Monge, Elaine (SCA) 


From: 

Sent: 

To: 

Cc: 

Subject: 

Attachments: 


Potter, David H. <David.Potter@wilsonelser,com> 

Friday, January 18, 2019 3:40 PM 
Breaches, Data {SCA) 

Das, Anjali C. 

AG MA Notification Letter - Eitringham 

AG MA - Notification Letter - Eitringham - Submission.pdf 


Please find attached a notification letter on behalf of our client, Eitringham Law Group, P.A. 

Best wishes, 

David 

David H. Potter 
Attorney at Law 

Wilson Elser Moskowitz Edelman & Dicker LLP 
55 West Monroe Street - Suite 3800 
Chicago, IL 60603-5001 
312.821.6106 (Direct) 

312.704.0550 (Main) 

312.704.1522 (Fax) 
david.potter@wilsonelser.com 


CONFIDENTIALITY NOTICE: This electronic message is intended to be 
viewed only by the individual or entity to whom it is addressed. 

It may contain information that is privileged, confidential and 
exempt from disclosure under applicable law. Any dissemination, 
distribution or copying of this communication is strictly prohibited 
without our prior permission. If the reader of this message is not 
the intended recipient, or the employee or agent responsible for 
delivering the message to the intended recipient, or if you have 
received this communication in error, please notify us immediately by 
return e-mail and delete the original message and any copies of it 
from your computer system. 

For further information about Wilson, Elser, Moskowitz, Edelman & 
Dicker LLP, please see our website at www.wilsonelser.com or refer to 
any of our offices. 

Thank you, 
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WILSON ELSER 

WUSON BLUER M05KOWJT2 ED6LMAN * PICKER LLP 


January 18, 2019 


Anjali C. Das 
312.821.6164 (direct) 
Anjali.Dast@wi!sonelser, com 


Via Online Submission and/or Email 


Attorney General Maura Healey 

Office of the Attorney General 
One Ashburton Place 
Boston, MA 02108-1518 
ago@,state.ma.us 

Undersecretary John C. Chapman 

Office of Consumer Affairs and Business Regulation 
10 Park Plaza, Suite 5170 
Boston, MA 02116 
data,breaches@state.ma.us 


Re: Data Security Incident 

Dear Attorney General Healey: 

We represent Eltringham Law Group, P.A. (“ELG”), located in Boca Raton, FL, with respect to a potential 
data security incident described in more detail below. ELG takes the security and privacy of the information 
in its control very seriously, and has taken steps to prevent a similar incident from occurring in the future. 

1. Nature of the security incident. 

At the end of November, 2018, ELG learned that an unauthorized person attempted to fraudulently wire 
funds from an ELG controlled bank account. ELG quickly took action and notified its IT department of 
the incident and an investigation was undertaken. ELG retained a computer forensic company to conduct 
a detailed forensic investigation to determine how the unauthorized person obtained the information 
necessary to perpetrated the attempted fraud and what, if any, additional information may have been 
accessible to the unauthorized person. As a result of its investigation, on December 5, 2018, ELG 
discovered that two email accounts were potentially accessed by an unauthorized user and that personal 
information, including name, Social Security number, driver’s license number and/or personal health 
information may have been accessible during the period of unauthorized access to the email accounts. 


55 West Monroe Street, Suite 3000 • Chicago, IL 60603 • p 312.704.0550 • f 312.704.1522 


Albany * Atlanta • Austin • Baltimore • Beaumont • Boslon • Chicago * Dallas • Denver * Edwardsvlite » Garden Ctty * Hartford • Houston * Indiana * Kenlucky 
las Vegas • London ■ Los Angeles • Miami ■ Michigan * Milwaukee » New Jersey • New Orleans • New York • Orlando ■ Philadelphia • Phoenix ■ San Diego 
Sart Francisco * Sarasota • Slamlord • Virginia • Washington, DC ► West Palm Beach * White Plains 

wllsortelser.com 
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2. Number of Massachusetts residents affected. 

A total of three (3) Massachusetts residents are known to have been potentially affected by this incident. 
Notification letters to these individuals were mailed on January 18, 2019, by first class mail. A sample 
copy of the notification letter is included with this letter. 

3. Steps taken. 

ELG has taken steps to prevent a similar event from occurring in the future, and to protect the privacy and 
security of potentially affected individuals’ information. This includes, changing all passwords, increasing 
employee cyber security awareness training, implementing enhanced authentication controls and more 
robust email password policies for employees. ELG has also undertaken a review and, if necessary, an 
update of existing policies and procedures related to personal information. ELG has also provided 
potentially affected individuals with identity theft restoration and credit monitoring services for a period of 
twelve (12) months at no cost to the individuals, through Kroll. 

4. Contact information. 

ELG remains dedicated to protecting the sensitive information in its control. If you have any questions or 
need additional information, please do not hesitate to contact me at Aniati,Das@wilsonelser.com or (312) 
821-6164. 


Very truly yours, 

Wilson Elser Moskowitz Edelman & Dicker LLP 



Enclosure. 


2644832v.l 















ELTRINGHAM 

-LAW GSOUP- 

«Date» (Format: Month Day, Year) 

«MemberFirstName» «WiemberMiddleName» «MemberLastName» «Suffix» 

«Address1» 

«Address2» 

«City», «State» «ZipCode» 


Dear «MemberFirstName» «MemberLast.Narne», 

We are writing to inform you of a data security incident at Eltringham Law Group {“ELG”) that may have resulted in the 
disclosure of your personal information, including your name, health information, and/or Social Security number. We 
sincerely apologize for any inconvenience or concern this incident may cause. This letter contains information about 
what happened, steps you can take to protect yourself, and resources we are making available to you. 

ELG learned that an unauthorized individual attempted to fraudulently wire funds from an ELG controlled account. 
ELG immediately launched an investigation to determine what happened. ELG retained a computer forensic firm to 
help identify what systems may have been accessed by unauthorized individuals and what information may have 
been accessible. As a result of that investigation, on December 5, 2018, we determined that some of your personal 
information, including your name, address, date of birth, Social Security number, driver's license number and limited 
health information may have been accessible by an unauthorized individual. 

We have no evidence of the misuse of your information as a result of this incident, however, out of an abundance of 
caution and as a safeguard, we have secured the services of Kroll to provide identity monitoring at no cost to you 
for one year. Kroll is a global leader in risk mitigation and response, and their team has extensive experience helping 
people who have sustained an unintentional exposure of confidential data. Your identity monitoring services include 
Credit Monitoring, Fraud Consultation, and Identity Theft Restoration. 

Visit «IDMonitoringURL» to activate and take advantage of your identity monitoring services. 

You have until «Date» to activate your identity monitoring services. 

Membership Number. «Member ID» 

To receive credit services by mail instead of online, please cal! 1-???-???-????. Additional information describing your 
services is included with this letter. 


We take the security of all information in our control very seriously and are taking steps to help prevent a similar event 
from occurring in the future. This includes increasing employee cybersecurity awareness training, implementing 
enhanced authentication controls and more robust email password policies for our employees, and adding additional 
security measures surrounding our internal and external communications of personal information. 

Again, we sincerely apologize for any concern or inconvenience this may cause you, and we remain dedicated to 
protecting your information, now and in the future. Nothing is more important to us than your trust and we will continue 
to do whatever it takes to honor that trust because YOU are the lifeblood of our business. 


If you have questions, please do not hesitate to call 1-???-???-????, Monday through Friday, 9:00 a.m. to 6:30 p.m. 
Eastern Time. Please have your membership number ready. 


Sincerely, 



David Eltringham 
CEO & Founder 
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Additional Important Information 


For residents of Hawaii, Michigan, Missouri, Virginia, Vermont, and North Carolina: 

It is recommended by state law that you remain vigilant for incidents of fraud and identity theft by reviewing credit card account 
statements and monitoring your credit report for unauthorized activity. 

For residents of Illinois, Iowa, Maryland, Missouri, North Carolina, Oregon, and West Virginia: 

It is required by state laws to inform you that you may obtain a copy of your credit report, free of charge, whether or not you 
suspect any unauthorized activity on your account. You may obtain a free copy of your credit report from each of the three 
nationwide credit reporting agencies. To order your free credit report, please visit www.annualcreditreport.com, or call toll-free 
at 1-877-322-8228. You can also order your annual free credit report by mailing a completed Annual Credit Report Request Form 
(available at https://www.consumer.ftc.gov/articles/0155-free-credit-reports) to: Annual Credit Report Request Service, RO. Box 
105281, Atlanta, GA, 30348-5281. 

For residents of Iowa: 

State law advises you to report any suspected identity theft to law enforcement or to the Attorney General, 

For residents of Oregon: 

State laws advise you to report any suspected identity theft to law enforcement, including the Attorney General, and the Federal 
Trade Commission. 


For residents of Maryland, Rhode Island, Illinois, and North Carolina: 


You can obtain information from the Maryland and North Carolina Offices of the Attorney General and the Federal Trade 
Commission about fraud alerts, security freezes, and steps you can take toward preventing identity theft. 


Maryland Office of the 
Attorney General 

Consumer Protection Division 
200 St. Paul Place 
Baltimore, MD 21202 
1-888-743-0023 
www.oag.state.md.us 


Rhode Island Office of the 
Attorney General 

Consumer Protection 
150 South Main Street 
Providence Rl 02903 
1-401-274-4400 
www.riag.ri.gov 


North Carolina Office of the 
Attorney General 

Consumer Protection Division 
9001 Maii Service Center 
Raleigh, NC 27699-9001 
1-877-566-7226 
www.ncdoj.com 


Federal Trade Commission 

Consumer Response Center 
600 Pennsylvania Ave, NW 
Washington, DC 20580 
1-877-IDTHEFT (438-4338) 
www.ftc.gov/idtheft 


For residents of Massachusetts: 

It is.required by state law that you are informed of your right to obtain a police report if you are a victim of identity theft 


For residents of all states: 


Fraud Alerts: You can place fraud alerts with the three credit bureaus by phone and online with Equifax (https://assets.equifax. 
com/assets/personal/Fraud_Alert_Request_Form.pdf) or Experian (https://www.experian.com/fraud/center.htmi). A fraud alert 
tells creditors to follow certain procedures, including contacting you, before they open any new accounts or change your existing 
accounts. For that reason, placing a fraud alert can protect you, but also may delay you when you seek to obtain credit. As of 
September 21, 2018, initial fraud alerts last for one year. Victims of identity theft can also get an extended fraud alert for seven 
years. The phone numbers for all three credit bureaus are at the bottom of this page. 

Monitoring: You should always remain vigilant and monitor your accounts for suspicious or unusual activity. 

Security Freeze: You also have the right to place a security freeze on your credit report. A security freeze is intended to prevent 
credit, loans, and services from being approved in your name without your consent. To place a security freeze on your credit 
report, you need to make a request to each consumer reporting agency. You may make that request by certified mail, overnight 
mail, regular stamped mail, or by following the instructions found at the websites listed below. The following information must 
be included when requesting a security freeze (note that if you are requesting a credit report for your spouse or a minor under 
the age of 16, this information must be provided for him/her as well): (1) full name, with middle initial and any suffixes; (2) Social 
Security number; (3) date of birth; (4) current address and any previous addresses for the past five years; and (5) any applicable 
incident report or complaint with a law enforcement agency or the Registry of Motor Vehicles. The request must also include a 
copy of a government-issued identification card and a copy of a recent utility bill or bank or insurance statement. It is essential 
that each copy be legible, display your name and current mailing address, and the date of issue. As of September 21, 2018, it 
is free to place, lift, or remove a security freeze. You may also place a security freeze for children under the age of 16. You may 
obtain a free security freeze by contacting any one or more of the following national consumer reporting agencies: 


Equifax Security Freeze 

P.O. Box 105788 
Atlanta, GA 30348 
www.freeze.equifax.com 
800-525-6285 


Experian Security Freeze 

P.O. Box 9554 
Allen, TX 75013 
www.experian.com/freeze 
888-397-3742 


TransUnion (FVAD) 

P.O. Box 2000 
Chester, PA 19022 
freeze.transunion.com 
800-680-7289 


More information can also be obtained by contacting the Federal Trade Commission listed above. 










Kroll. 

TAKE ADVANTAGE OF YOUR IDENTITY MONITORING SERVICES 

You’ve been provided with access to the following services' from Kroll: 

Single Bureau Credit Monitoring 

You will receive alerts when there are changes to your credit data—for instance, when a new line of credit is applied 
for in your name. If you do not recognize the activity, you’ll have the option to call a Kroll fraud specialist, who can help 
you determine if it’s an indicator of identity theft. 

Fraud Consultation 

You have unlimited access to consultation with a Kroll fraud specialist. Support includes showing you the most 
effective ways to protect your identity, explaining your rights and protections under the law, assistance with fraud 
alerts, and interpreting how personal information is accessed and used, including investigating suspicious activity 
that could be tied to an identity theft event. 

Identity Theft Restoration 

If you become a victim of identity theft, an experienced Kroll licensed investigator will work on your behalf to resolve 
related issues. You will have access to a dedicated investigator who understands your issues and can do most of the 
work for you. Your investigator can dig deep to uncover the scope of the identity theft, and then work to resolve it. 



1 Kroll’s activation website is only compatible with the current version or one version earlier of Internet Explorer, Chrome, Firefox, and Safari, 
To receive credit services, you must be over the age of 18 and have established credit in the U.S., have a Social Security number in your 
name, and have a U.S. residential address associated with your credit tile. 
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January 18, 2019 AnjaiiCDas 

312,821.6164 (direct) 
AnjaIi.Dast@wilsoneiscr.com 


Via Online Submission and/or Email 


Attorney General Maura Healey 
Office of the Attorney General 
One Ashburton Place 
Boston, MA 02108-1518 
ago@state.ma.us 

Undersecretary John C, Chapman 

Office of Consumer Affairs and Business Regulation 

10 Park Plaza, Suite 5170 

Boston, MA 02116 

data, breaches@state.ina. us 


Re: Data Security Incident 

Dear Attorney General Healey: 

We represent Eltringham Law Group, PA. (“ELG”), located in Boca Raton, FL, with respect to a potential 
data security incident described in more detail below. ELG takes the security and privacy of the information 
in its control very seriously, and has taken steps to prevent a similar incident from occurring in the future. 

1. Nature of the security incident. 

At the end of November, 2018, ELG learned that an unauthorized person attempted to fraudulently wire 
funds from an ELG controlled bank account. ELG quickly took action and notified its IT department of 
the incident and an investigation was undertaken. ELG retained a computer forensic company to conduct 
a detailed forensic investigation to determine how the unauthorized person obtained the information 
necessary to perpetrated the attempted fraud and what, if any, additional information may have been 
accessible to the unauthorized person. As a result of its investigation, on December 5, 2018, ELG 
discovered that two email accounts were potentially accessed by an unauthorized user and that personal 
information, including name, Social Security number, driver’s license number and/or personal health 
information may have been accessible during the period of unauthorized access to the email accounts. 
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2 . Number of Massachusetts residents affected. 

A total of three (3) Massachusetts residents are known to have been potentially affected by this incident. 
Notification letters to these individuals were mailed on January 18, 2019, by first class mail. A sample 
copy of the notification letter is included with this letter. 

3. Steps taken. 

ELG has taken steps to prevent a similar event from occurring in the future, and to protect the privacy and 
security of potentially affected individuals’ information. This includes, changing all passwords, increasing 
employee cyber security awareness training, implementing enhanced authentication controls and more 
robust email password policies for employees. ELG has also undertaken a review and, if necessary, an 
update of existing policies and procedures related to personal information. ELG has also provided 
potentially affected individuals with identity theft restoration and credit monitoring services for a period of 
twelve (12) months at no cost to the individuals, through Rroll. 

4. Contact information. 

ELG remains dedicated to protecting the sensitive information in its control. If you have any questions or 
need additional information, please do not hesitate to contact me at Aniali,Das@wiisonel$er.com or (312) 
821-6164. 


Very truly yours, 

Wilson Elser Moskowitx Edelman & Dicker LLP 



Enclosure. 
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